Curated Cyber Threat Intelligence

Threat Feed

Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.

scheduleUpdated 2026-09-04 · 02:17 UTC
articleTotal: 1172 reports

Filtered Reports

30 / 30 results
Active filter:tag: #npm✕ clear
Attackers abuse npm mirrors as free hosting for Cloudflare phishing pageshighbug_reportVulnerability
bug_reportVulnerability

Attackers abuse npm mirrors as free hosting for Cloudflare phishing pages

npm registry and public mirrors (UNPKG, npmmirror). Organizations using these mirrors to serve package content. At least 24 malicious packages identified hosting fake Cloudflare CAPTCHA pages.

npm25 Aug · 19:39 UTC
24 npm packages abuse unpkg mirrors as phishing infrastructurehighbug_reportVulnerability
bug_reportVulnerability

24 npm packages abuse unpkg mirrors as phishing infrastructure

24 malicious npm packages (e.g., bgzxcuite2, prezdentkxheiw, egair0810) hosted on npm registry and mirrored on unpkg.com and similar CDN services. Affects users who click links to these mirrored HTML pages, not developers installing packages directly…

npm25 Aug · 09:52 UTC
14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoorhighbug_reportVulnerability
bug_reportVulnerability

14 trojanized npm packages deliver AI-powered RedC2 4.0 Linux backdoor

14 npm packages (streak-metrics-math, kit-map-vim, streak-map-cache, streak-map-kit, map-streak-kit, streak-cache-map, streak-calc-metrics, streak-calc-math, streak-math-abz, streak-metricsaz, streak-math-metrics, streak-metricazbd, streak-metricsazb…

npm21 Aug · 16:53 UTC
Nearly 800 malicious npm packages deliver cross-platform RAT via typosquattingcriticalbug_reportVulnerability
bug_reportVulnerability

Nearly 800 malicious npm packages deliver cross-platform RAT via typosquatting

npm registry: ~800 packages using typosquatting and AI-generated names. Targets all Node.js developers on Windows, macOS (x64/ARM64), and Linux (x64/ARM64). Delivers WEL1DROPPER leading to Sliver C2 framework and platform-specific infostealers.

npm7 Aug · 16:48 UTC
ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2highbug_reportVulnerability
bug_reportVulnerability

ChainDrop npm worm infects 400+ packages, steals secrets via blockchain C2

Over 400 npm packages including widely used packages like keyv and cacheable-request. Affects developer workstations, CI/CD pipelines (especially GitHub Actions), cloud environments, and downstream software users.

npm6 Aug · 20:26 UTC
Trojanized npm packages use blockchain to hide C2 IPs in supply chain attackhighbug_reportVulnerability
bug_reportVulnerability

Trojanized npm packages use blockchain to hide C2 IPs in supply chain attack

Two npm packages: "bianira-ui" (109 downloads) and "fluid-type-ui" (587 downloads), published July 28, 2026 by users "npmuser1101" and "npmuser3002". Packages now removed from npm.

npm5 Aug · 11:41 UTC
Credential-stealing worm compromises 400+ npm packages via auto-propagationcriticalbug_reportVulnerability
bug_reportVulnerability

Credential-stealing worm compromises 400+ npm packages via auto-propagation

Over 400 npm packages across multiple unrelated publishers, including keyv, flat-cache, cache-manager, and other major enterprise software ecosystem packages. Affects developer workstations and CI/CD environments with npm lifecycle scripts enabled.

npm4 Aug · 21:46 UTC
ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloadscriticalbug_reportVulnerability
bug_reportVulnerability

ChainDrop worm compromises 1,300+ npm packages with 2B monthly downloads

Over 1,300 npm packages (1,381 versions) including Keyv, Cacheable, flat-cache, and file-entry-cache. Attack originated from compromised GitHub account of Keyv maintainer.

npm4 Aug · 13:24 UTC
npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hookscriticalbug_reportVulnerability
bug_reportVulnerability

npm worm from keyv@6.0.0 poisons 353+ packages, steals credentials via hooks

npm packages: keyv@6.0.0 and at least 353 poisoned versions across 79 package names (SafeDep verified); broader estimates reach 868 packages. Affects developers and CI/CD environments using npm clients prior to npm 12, Claude Code, and VS Code.

npm4 Aug · 11:30 UTC
18 malicious npm packages deliver cross-platform RAT to Alibaba developershighbug_reportVulnerability
bug_reportVulnerability

18 malicious npm packages deliver cross-platform RAT to Alibaba developers

18 npm packages targeting Alibaba developer tool users, primarily Chinese-speaking environments. Key packages: lib-mtop (v1.0.1-1.0.3), aone-kit, aone-kit-cli, aone-sandbox, local-config-parser, smart-config-manager, and 12 others.

Alibaba3 Aug · 16:43 UTC
North Korea-linked actors compromise npm packages debug, chalk, axioshighbug_reportVulnerability
bug_reportVulnerability

North Korea-linked actors compromise npm packages debug, chalk, axios

Node Package Manager (npm) ecosystem: typo-crypto (March 2025), debug and chalk (September 2025, ~10% of cloud environments affected within 2 hours), axios (March 2026, 100M+ weekly downloads).

npm30 Jul · 16:13 UTC
North Korea linked to npm supply chain attacks on debug, chalk, axioscriticalbug_reportVulnerability
bug_reportVulnerability

North Korea linked to npm supply chain attacks on debug, chalk, axios

npm packages debug, chalk, axios, typo-crypto, and Mastra (over 2 billion weekly downloads combined). Attacks spanned March 2025 through March 2026. Maintainer accounts compromised via phishing; malicious code injected to steal cryptocurrency wallet…

npm30 Jul · 04:05 UTC
Seven malicious npm packages target Vite ecosystem with blockchain C2 RAThighbug_reportVulnerability
bug_reportVulnerability

Seven malicious npm packages target Vite ecosystem with blockchain C2 RAT

npm package ecosystem, specifically projects using Vite frontend tooling. Seven malicious packages identified in the ViteVenom campaign. Any JavaScript/Node.js development environments that installed these packages are compromised.

npm17 Jul · 16:54 UTC
North Korean actors deploy malicious npm packages to steal developer secretshighbug_reportVulnerability
bug_reportVulnerability

North Korean actors deploy malicious npm packages to steal developer secrets

npm ecosystem: malicious packages "rollup-packages-polyfill-core" and "rollup-runtime-polyfill-core" impersonating legitimate "rollup-plugin-polyfill-node".

npm3 Jul · 14:07 UTC
Hijacked npm and Go packages deploy cross-platform stealer via VS Codehighbug_reportVulnerability
bug_reportVulnerability

Hijacked npm and Go packages deploy cross-platform stealer via VS Code

Compromised npm and Go packages targeting developers using Microsoft Visual Studio Code on Windows, Linux, and macOS. Attack bypasses npm v12 lifecycle script protections by abusing VS Code task execution.

npm29 Jun · 03:36 UTC
Miasma malware compromises npm packages LeoPlatform and RStreamshighbug_reportVulnerability
bug_reportVulnerability

Miasma malware compromises npm packages LeoPlatform and RStreams

npm packages LeoPlatform and RStreams compromised by Miasma malware family. Attack extends to GitHub Actions workflows and Go ecosystem. Organizations using these packages or dependent projects are affected.

npm26 Jun · 09:05 UTC
Malicious npm packages deliver Windows RAT to JavaScript developershighbug_reportVulnerability
bug_reportVulnerability

Malicious npm packages deliver Windows RAT to JavaScript developers

Three npm packages (aes-decode-runner-pro, postcss-minify-selector, postcss-minify-selector-parser) published within the past month. Total downloads: 145-615 per package. Affects Windows-based development environments using npm package manager.

npm23 Jun · 06:54 UTC
North Korean APT compromised 140+ npm packages via Mastra AI frameworkhighbug_reportVulnerability
bug_reportVulnerability

North Korean APT compromised 140+ npm packages via Mastra AI framework

Mastra AI framework and over 140 dependent npm packages. Organizations using Mastra AI or downstream dependencies in Node.js/JavaScript applications are affected.

Mastra AI20 Jun · 12:09 UTC
Weekly threat roundup: Claude abuse, npm poisoning, phishing campaignshighbug_reportVulnerability
bug_reportVulnerability

Weekly threat roundup: Claude abuse, npm poisoning, phishing campaigns

Multiple platforms and products: Claude AI chat interface, npm package ecosystem (NastyC2), OAuth device-code flows, browser extensions (unspecified), macOS systems, cloud management agents, and internet-exposed edge devices.

Claude18 Jun · 13:27 UTC
Poisoned npm package compromises 140+ projects via postinstall payloadhighbug_reportVulnerability
bug_reportVulnerability

Poisoned npm package compromises 140+ projects via postinstall payload

140+ projects using a malicious npm package containing a hidden postinstall script. Affects Node.js/JavaScript development environments consuming npm dependencies. Specific package name not disclosed in summary.

npm18 Jun · 01:43 UTC
Supply chain attack compromises 144 Mastra npm packages via hijacked accountcriticalbug_reportVulnerability
bug_reportVulnerability

Supply chain attack compromises 144 Mastra npm packages via hijacked account

144 npm packages in the @mastra/* namespace (Mastra AI framework for JavaScript/TypeScript). Attack vector: compromised npm contributor account (ehindero). All downstream projects using affected Mastra packages are potentially impacted.

Mastra17 Jun · 05:38 UTC
npm v12 disables install scripts by default to block supply chain attackshighbug_reportVulnerability
bug_reportVulnerability

npm v12 disables install scripts by default to block supply chain attacks

npm version 12 and later. All Node.js projects using npm for package management. Breaking change affects packages that legitimately rely on install/postinstall lifecycle hooks.

GitHub11 Jun · 04:23 UTC
npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkitcriticalbug_reportVulnerability
bug_reportVulnerability

npm supply chain attack: 50+ packages deliver IronWorm stealer and rootkit

npm ecosystem: over 50 compromised legitimate packages. Affects developers using npm for JavaScript/Node.js projects. IronWorm targets developer credentials and source code with eBPF kernel-level persistence.

npm5 Jun · 16:05 UTC
Malicious npm package codexui-android steals OpenAI tokens, 29K downloadshighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package codexui-android steals OpenAI tokens, 29K downloads

npm package codexui-android (all versions). Targets developers using OpenAI Codex APIs. Affects organizations with Node.js/npm development environments where this package was installed.

OpenAI1 Jun · 07:31 UTC
33 malicious npm packages deployed in dependency confusion recon campaignhighbug_reportVulnerability
bug_reportVulnerability

33 malicious npm packages deployed in dependency confusion recon campaign

npm ecosystem; organizations using private npm packages with names vulnerable to dependency confusion attacks. Affects developer workstations, CI/CD pipelines, and build environments that may inadvertently install public packages instead of intended…

npm29 May · 22:06 UTC
Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentialshighperson_alertThreat Actor
person_alertThreat Actor

Mini Shai-Hulud: Typosquatted npm Packages Target Developer Credentials

Mini Shai-Hulud is a threat actor campaign focused on compromising software development environments through supply chain attacks. The actor leverages typosquatting techniques against the npm package ecosystem to distribute malicious packages that ma…

npm29 May · 01:04 UTC
Malicious npm package targets Claude AI user data directoryhighbug_reportVulnerability
bug_reportVulnerability

Malicious npm package targets Claude AI user data directory

npm package "mouse5212-super-formatter" (all versions). Targets developers using Anthropic Claude AI tools with access to /mnt/user-data directory. Affects Node.js development environments where the malicious package was installed.

npm27 May · 13:44 UTC
TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.iocriticalbug_reportVulnerability
bug_reportVulnerability

TrapDoor campaign deploys credential stealers across npm, PyPI, Crates.io

34+ malicious packages (384+ versions) distributed across npm (Node.js), PyPI (Python), and Crates.io (Rust) repositories. Campaign active since May 2026. Affects developers and CI/CD pipelines consuming packages from these ecosystems.

npm25 May · 03:59 UTC
Compromised @antv npm packages deploy credential-stealing malwarecriticalbug_reportVulnerability
bug_reportVulnerability

Compromised @antv npm packages deploy credential-stealing malware

Multiple @antv npm packages compromised with Mini Shai-Hulud malware. Affects Linux-based CI/CD pipelines using npm install. Targets credentials from GitHub, AWS, Kubernetes, HashiCorp Vault, npm, and 1Password.

npm20 May · 15:48 UTC
Over 600 malicious npm packages published in Shai-Hulud campaignhighbug_reportVulnerability
bug_reportVulnerability

Over 600 malicious npm packages published in Shai-Hulud campaign

npm ecosystem: 600+ malicious packages published by threat actors. Affects organizations using npm for JavaScript/Node.js dependency management. Specific package names not provided in summary.

npm19 May · 12:30 UTC